github.com
https://github.com/yj94/Yj_learning/blob/b597925953d8bbb286a63f0019bb547c1617cb61/Week16/D-LINK-POC.md CVE-2024-33112
HIGH
D-Link DIR-845L HNAP OS Command Injection
Record summary
CVE-2024-33112 has a selected CVSS score of 7.5 (high).
Description
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 26, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DIR-845LBrowse D-Link / DIR-845LDefault status: unknown | VulnCheck, CVE List | 1.01KRb03 | affected |
References
3github.com
https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33112